From: "Frédéric Danis" <frederic.danis@collabora.com>
To: linux-bluetooth@vger.kernel.org
Subject: [PATCH BlueZ v4 1/6] mgmt: Add Security Level Changed event
Date: Tue, 29 Sep 2026 12:19:48 +0200 [thread overview]
Message-ID: <20260929101953.254969-2-frederic.danis@collabora.com> (raw)
In-Reply-To: <20260929101953.254969-1-frederic.danis@collabora.com>
This provides a TLV list of values related to the security level of
the connection to a remote device.
Currently Security Level and Encryption type are implemented.
---
v1->v2: Fix struct mgmt_ev_security_level_changed definition
v2->v3: Re-work Security Level possible values in mgmt-protocol.rst to be in
with other *-protocol.rst files
v3->v4: Following changes in kernel patch, replace tlv_count by tlv_length
doc/mgmt-protocol.rst | 45 +++++++++++++++++++++++++++++++++++++++++++
lib/bluetooth/mgmt.h | 15 +++++++++++++++
2 files changed, 60 insertions(+)
diff --git a/doc/mgmt-protocol.rst b/doc/mgmt-protocol.rst
index f0564075f..f4c6822bf 100644
--- a/doc/mgmt-protocol.rst
+++ b/doc/mgmt-protocol.rst
@@ -5521,3 +5521,48 @@ The Supervision_Timeout parameter specifies the supervision timeout in units
of 10 ms.
This event will be sent to all management sockets.
+
+Security Level Changed
+``````````````````````
+
+:Event Code: 0x0034
+:Controller Index: <controller_id>
+:Event Parameters: Address (6 Octets)
+:...: Address_Type (1 Octet)
+:...: TLV_Length (1 Octet)
+:...: TLV_List (variable)
+
+This event indicates that the security level of a device has changed.
+
+Possible values for the TLV type parameter:
+
+.. csv-table::
+ :header: "Type", "Description"
+ :widths: auto
+
+ 0x0000, Security Level
+ 0x0001, Encryption type
+
+Possible values for the Security Level type:
+
+.. csv-table::
+ :header: "Value", "Security Level", "Link Key Type", "Encryption"
+ :widths: auto
+
+ **BT_SECURITY_SDP**, 0 (SDP Only), None, Not required
+ **BT_SECURITY_LOW**, 1 (Low), Unauthenticated, Not required
+ **BT_SECURITY_MEDIUM**, 2 (Medium - default), Unauthenticated, Desired
+ **BT_SECURITY_HIGH**, 3 (High), Authenticated, Required
+ **BT_SECURITY_FIPS** (since Linux 3.15), 4 (Secure Only), Authenticated (P-256 based Secure Simple Pairing and Secure Authentication), Required
+
+Possible values for the Encryption type:
+
+.. csv-table::
+ :header: "Value", "Description"
+ :widths: auto
+
+ 0x00, No encryption
+ 0x01, E0 encryption
+ 0x02, AES-CCM encryption
+
+This event will be sent to all management sockets.
diff --git a/lib/bluetooth/mgmt.h b/lib/bluetooth/mgmt.h
index 098be2074..af71be828 100644
--- a/lib/bluetooth/mgmt.h
+++ b/lib/bluetooth/mgmt.h
@@ -1142,6 +1142,20 @@ struct mgmt_ev_conn_subrate {
uint16_t supv_timeout;
} __packed;
+#define MGMT_CONN_SEC_ENCRYPT_NONE 0x00
+#define MGMT_CONN_SEC_ENCRYPT_E0 0x01
+#define MGMT_CONN_SEC_ENCRYPT_AES_CCM 0x02
+
+#define MGMT_SEC_LEVEL_CHANGED_PARAM_LEVEL 0x0000
+#define MGMT_SEC_LEVEL_CHANGED_PARAM_ENC_TYPE 0x0001
+
+#define MGMT_EV_SECURITY_LEVEL_CHANGED 0x0034
+struct mgmt_ev_security_level_changed {
+ struct mgmt_addr_info addr;
+ uint8_t tlv_length;
+ uint8_t tlv_data[];
+} __packed;
+
static const char *mgmt_op[] = {
"<0x0000>",
"Read Version",
@@ -1291,6 +1305,7 @@ static const char *mgmt_ev[] = {
"Mesh Packet Found",
"Mesh Packet Complete",
"Connection Subrate",
+ "Security Level Changed",
};
static const char *mgmt_status[] = {
--
2.43.0
next prev parent reply other threads:[~2026-09-29 10:20 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 10:19 [PATCH BlueZ v4 0/6] mgmt/device: report link security level to D-Bus clients Frédéric Danis
2026-09-29 10:19 ` Frédéric Danis [this message]
2026-09-29 14:42 ` bluez.test.bot
2026-09-29 10:19 ` [PATCH BlueZ v4 2/6] mgmt-tester: Add Security Level Changed event tests Frédéric Danis
2026-09-29 10:19 ` [PATCH BlueZ v4 3/6] monitor: Add support for Mgmt Security Level changed event Frédéric Danis
2026-09-29 10:19 ` [PATCH BlueZ v4 4/6] device: Add SecurityLevel properties to org.bluez.Device1 Frédéric Danis
2026-09-29 10:19 ` [PATCH BlueZ v4 5/6] org.bluez.Device: Add Security Level related properties Frédéric Danis
2026-09-29 10:19 ` [PATCH BlueZ v4 6/6] client: Display SecurityLevel in device info Frédéric Danis
2026-10-01 17:40 ` [PATCH BlueZ v4 0/6] mgmt/device: report link security level to D-Bus clients patchwork-bot+bluetooth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929101953.254969-2-frederic.danis@collabora.com \
--to=frederic.danis@collabora.com \
--cc=linux-bluetooth@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox